CVE-2019-14070: Use After Free
Possible use after free issue in pcm volume controls due to race condition exist in private data used in mixer controls in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, IPQ4019, IPQ6018, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9615, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCS605, QM215, Rennell, SA6155P, Saipan, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14070?
The severity of CVE-2019-14070 is classified as critical due to the potential for exploitation leading to memory corruption.
How do I fix CVE-2019-14070?
To fix CVE-2019-14070, users should apply the latest patches and firmware updates provided by Qualcomm or device manufacturers.
What systems are affected by CVE-2019-14070?
CVE-2019-14070 affects various Qualcomm Snapdragon platforms across automotive, consumer IoT, mobile, and wearable devices.
What type of vulnerability is CVE-2019-14070?
CVE-2019-14070 is a use-after-free vulnerability that can be triggered due to a race condition in the audio mixer controls.
Can CVE-2019-14070 be exploited remotely?
Yes, CVE-2019-14070 can be exploited remotely, potentially allowing an attacker to execute arbitrary code.